← Back to blog

Who actually holds the key when you automate your investing

September 25, 2026 · Aurono Labs
educationarchitecturetrust

Who holds the key

Imagine handing someone a set of instructions: move money from this account when this happens. Now imagine two different setups for who actually carries that instruction out.

In the first, you hand the instructions to a bank teller who has full authority over the account. The teller follows your instructions faithfully, every time, but the teller could, in principle, do something else with that money. You’re trusting the teller, not the instructions.

In the second, the instructions trigger a key that only you hold, and nobody, including whoever wrote the instructions, has any other way to move that money. There’s no teller to trust. The key is the only door, and you’re the only one holding it.

That’s the actual difference between custodial and self-custodial: a fact about who holds a key.

What custody actually means, mechanically

Custody is a narrower question than it sounds: when a transaction is signed, whose key actually does the signing? On a regulated crypto exchange, the exchange holds the private keys to its own wallets, and your balance is really a ledger entry in the exchange’s own database, backed by assets the exchange controls. A rule-based tool can send the exchange an instruction, “place this order,” and never touch the funds directly. But the exchange still holds them. The exchange is still the one thing standing between the instruction and the money.

Self-custodial removes that middle layer entirely. Your own wallet holds a private key that only you control, and only a signature from that key can move anything out of it. Nothing else, not an exchange, not a bank, not the software running your rules, ever holds the funds itself. The software can construct a transaction and hand it to your wallet to sign. The software cannot sign anything on its own.

Where “non-custodial” claims get slippery

Plenty of platforms use the word “non-custodial” as a selling point, and plenty of them mean it honestly. But the word alone doesn’t tell you where the actual key lives. A smart contract can hold funds under rules nobody can override, which is genuinely self-custodial in spirit. A smart contract can also be paired with an admin key that its own operator controls. Picture a safe with a combination lock only you know, except the manufacturer kept a master key that opens every safe of that model. As long as that master key exists, the manufacturer can still open the safe whenever they want, no matter what combination you set. That quietly reintroduces exactly the trust problem the word was supposed to solve. Both setups can honestly call themselves “non-custodial” in some technical sense. Only one of them removes the trusted third party.

The right question is: if this platform disappeared tomorrow, who could still move my funds? If the honest answer is “only me, using a key I’ve always held,” the platform is genuinely self-custodial. If the answer involves anyone else’s signature, even a smart contract’s own admin key, it isn’t.

The honest version, in one sentence

Self-custodial means the only signature that can ever move your funds is yours, and that was true before the platform existed and stays true after it’s gone.

The takeaway

Custody comes down to which key actually signs. A regulated exchange holding your funds while a rule-based tool only ever sends instructions is a real, useful architecture, and it’s what Aurono Start is built on. A wallet only you hold, where nothing else can ever sign on your behalf, is a different and harder architecture to build correctly.

That second, harder version is exactly what Aurono Onchain is built around: a wallet you hold, not an account anyone else could ever touch.


Aurono runs your rules on your own device, whether the execution happens on a regulated exchange or directly on-chain. The rules are always yours. This post is just about where the actual keys live.

Read how Aurono Start earns trust.